If your team has worked with Europe's GDPR, you have a head start on India's DPDP Act 2023 — but assuming they are the same law with different names is a costly mistake. The DPDP Act is shorter, stricter in places, more lenient in others, and structured around distinctly Indian concepts. Here are the twelve differences that matter most in practice.
GDPR covers personal data in any form, including structured paper filing systems. The DPDP Act applies only to digital personal data — data collected digitally, or collected offline and later digitised. A paper register that is never scanned sits outside the Act; the moment it is digitised, it is in scope.
GDPR creates special categories (health, biometrics, religion, etc.) with stricter rules. The DPDP Act treats all personal data alike — there is no separate sensitive-data regime. The practical effect: obligations that GDPR reserves for special categories apply in India to every scrap of personal data you process.
GDPR offers six lawful bases, including the flexible "legitimate interests". The DPDP Act allows only two: consent, or one of the specifically listed legitimate uses (such as voluntary provision, employment purposes, medical emergencies and state functions). There is no general legitimate-interest basis to fall back on — if your processing doesn't fit a listed use, you need consent.
GDPR sets the digital age of consent at 16 (member states may lower it to 13). India sets it at 18 — significantly expanding who counts as a child. Any organisation serving teenagers — education, gaming, edtech, social platforms — must obtain verifiable parental consent and must not track, behaviourally monitor or target advertising at minors.
GDPR fines scale to 4% of global annual turnover. The DPDP Act sets fixed monetary ceilings — up to ₹250 crore for failing security safeguards, ₹200 crore for breach-notification failures and children's-data violations, ₹150 crore for SDF obligation breaches. For a small company, the Indian caps can be proportionally far harsher than 4% of turnover.
Under GDPR, individuals are notified only when a breach poses high risk to them. The DPDP framework requires notifying the Data Protection Board and each affected data principal — without a risk threshold. Operationally this is a much heavier duty: you must be able to identify exactly whose data was affected, quickly.
The DPDP Act grants four rights — access, correction and erasure, grievance redressal, and nomination. GDPR rights with no DPDP equivalent include data portability, the right to object, and restrictions on automated decision-making. The right to nominate someone to exercise your rights after death or incapacity is uniquely Indian.
GDPR imposes obligations only on controllers and processors. The DPDP Act also imposes duties on individuals — not to impersonate others, not to suppress material information, not to file false complaints — with a penalty up to ₹10,000. No GDPR parallel exists.
The DPDP Act creates a new institution: the Consent Manager, a Board-registered entity through which individuals can give, manage, review and withdraw consent across fiduciaries via an interoperable platform. GDPR has no equivalent — this is India borrowing from its account-aggregator playbook.
GDPR restricts transfers to countries lacking adequacy decisions (a whitelist approach). The DPDP Act permits transfers to any country except those specifically restricted by government notification (a blacklist approach) — more permissive by default, but subject to change at notification speed, and sectoral rules (like RBI data-localisation for payments) still apply on top.
GDPR requires DPOs based on the nature of processing. In India, only Significant Data Fiduciaries must appoint a DPO — and that DPO must be based in India and report to the board of directors.
DPDP consent notices must give the data principal the option to read them in English or any of the 22 languages in the Eighth Schedule of the Constitution — a localisation duty GDPR never contemplated.
If you are GDPR-compliant, roughly 60–70% of your machinery transfers: data mapping, security safeguards, breach playbooks, processor contracts. What needs Indian re-engineering: consent flows (no legitimate interests to lean on), children's data handling (18, verifiable parental consent), notice localisation, principal-facing breach notification, and Consent Manager readiness. A structured discovery and consent platform covers both regimes from one data inventory.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →
Get a personalised compliance assessment — free, no obligation.
Book a Free Assessment →